Impact
Improper neutralization of user input was discovered in Ceviz Informatics Inc. Web Design, allowing attacker supplied data to be reflected in a browser and executed as malicious JavaScript. The vulnerability can lead to credential theft, session hijacking, or tampering with user interactions with the web application, compromising confidentiality, integrity, and availability of user sessions.
Affected Systems
Ceviz Informatics Inc. Web Design is affected in all releases up to and including 25082026. No other vendors, products, or versions were listed by the CNA.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity with potential for moderate damage if exploited. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through crafted URLs or form input that browsers will reflect and execute. Exploitation requires only that a malicious user entice a victim to visit a malicious link or submit crafted data, making it realistic in phishing or social‑engineering scenarios.
OpenCVE Enrichment